ASD ISM 2149Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
Keep a current, approved list of remote monitoring and management (RMM) and remote access tools, and block anything not on it from running or connecting.
Plain language
Remote monitoring and management (RMM) tools and remote access tools (think AnyDesk, TeamViewer, ScreenConnect, Splashtop and similar) let someone see and control a computer from anywhere. That is exactly what IT teams and managed service providers need, and it is also exactly what an attacker wants. Cyber criminals routinely install a second, unsanctioned remote tool on a compromised machine because it looks like normal admin software, survives reboots and gives them a persistent, encrypted door back in. This control asks for three things. First, **develop** a list of the RMM and remote access tools your organisation has actually authorised. Second, **enforce** that list, so tools that are not on it cannot be installed, run or connect. Third, **maintain** the list, so it stays accurate as tools are added, replaced or retired. It matters because a remote tool you have not approved is indistinguishable from an intrusion. Without an authoritative list you cannot tell a technician's legitimate session from an attacker's, and without enforcement the list is just a document that nobody has to follow.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Sept 2026
Control Stack last updated
05 Sept 2026
E8 maturity levels
N/A
Official control statement
A list of authorised RMM tools and remote access tools is developed, enforced and maintained.
Why it matters
If no authorised list exists, or it is not enforced, anyone (staff, contractors, service providers or an attacker who has gained a foothold) can install whichever remote access tool they like. Unsanctioned tools become a persistent backdoor that blends in with normal administrative traffic, allowing attackers to return at will, move between systems and exfiltrate data while security teams see nothing unusual. A stale list creates the opposite failure: legitimate tools drop off the record and tools that should have been retired keep working, so enforcement decisions are made against the wrong baseline. Either way the organisation loses the ability to say with confidence which remote pathways into its environment are supposed to be there.
Operational notes
Day to day, the authorised list is the reference point for three routine activities.
Keep the list somewhere version-controlled or change-tracked so that who added or removed a tool, and when, can be shown later. Make sure service providers who support your environment are told which tools are permitted and that their contracts reflect it.
- **Requests for a new tool** (from IT, a business unit or a managed service provider) go through an approval step before the tool is added to the list and allowed by the enforcement controls. Until then the request is a no.
- **Enforcement** runs continuously in the background, typically through application control, endpoint protection rules, and network or firewall rules that block the executables, installers and outbound connections of tools that are not authorised. Blocked attempts should generate an alert, because a blocked remote tool on a workstation is often the first visible sign of an intrusion or of a service provider working outside agreed arrangements.
- **Maintenance** means the list is reviewed on a set cadence (and whenever a tool is deployed, replaced or decommissioned) so that it reflects what is actually in use. Retiring a tool should include removing it from endpoints and revoking its network allowances, not just deleting a line from the list.
Implementation tips
- IT operations, with the security team, inventories every RMM and remote access tool currently installed or in use across the organisation and its service providers by querying endpoint management and application discovery data, then records each tool, its owner, its purpose and its approval decision in a single authorised list.
- The security team defines the approval criteria and the change process for the list (who can request a tool, who approves it, and what must be checked before approval) and documents that process so additions and removals are consistent and traceable.
- Endpoint engineers enforce the list on workstations and servers by configuring application control or endpoint protection to allow only the authorised tools' executables, installers and services, and to block and alert on any other RMM or remote access software.
- Network engineers enforce the list at the perimeter by allowing outbound connections only to the relay and cloud services used by authorised tools, and blocking or alerting on connections to the known service endpoints of tools that are not authorised.
- The control owner schedules a periodic review of the list (and triggers a review whenever a tool is deployed, replaced or retired) that reconciles the list against what is actually installed, removes retired tools from endpoints and network allow rules, and records the review outcome and date.
Audit / evidence tips
- AskAsk for the current authorised list of RMM and remote access tools.Look atCheck that it names each tool, its owner and purpose, and who approved it and when, and that it has a review or version history.GoodA single authoritative list exists, is clearly owned, and shows recent dated changes rather than a one-off document.
- AskAsk for the process used to add a tool to, or remove a tool from, the list.Look atLook for defined approval criteria, named approvers, and examples of requests that were approved and requests that were declined.GoodAdditions and removals follow a documented process with evidence that it has actually been used, including at least one refusal.
- AskAsk for the endpoint configuration that enforces the list, such as application control or endpoint protection rules.Look atCheck that the allowed set matches the authorised list and that unlisted remote tools are blocked rather than merely logged, and confirm coverage across workstations and servers.GoodEnforcement rules mirror the list exactly, apply to all relevant systems, and a test of an unauthorised tool is blocked.
- AskAsk for network or firewall rules and alerts relating to remote access tool traffic.Look atLook for rules that permit only authorised tools' service endpoints and for alerts or block logs showing attempts by unauthorised tools.GoodOutbound access is restricted to authorised tools, and blocked attempts are visible to and reviewed by the security team.
- AskAsk for the most recent reconciliation of the list against what is actually installed, and for any decommissioning records.Look atCheck that discovered software was compared to the list, discrepancies were actioned, and retired tools were removed from endpoints and enforcement rules.GoodThe list matches reality, the review is dated and signed off, and retired tools no longer appear in inventory or allow rules.
Cross-framework mappings
How ISM-2149 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(2)expand_less | ||
| Annex A 5.15 | ISM-2149 requires the organisation to control which RMM and remote access tools are permitted, effectively limiting which mechanisms can ... | |
| Annex A 6.7 | ISM-2149 requires the organisation to develop, enforce and maintain an authorised list of RMM and remote access tools, and to prevent una... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(3)expand_less | ||
| E8-AC-ML1.1 | ISM-2149 requires a controlled, enforced allow-list of authorised RMM and remote access tools and the blocking of anything not authorised | |
| E8-AC-ML1.3 | ISM-2149 requires organisations to maintain an authorised list of RMM and remote access tools and enforce it by blocking unauthorised tools | |
| E8-AC-ML2.1 | ISM-2149 requires an enforced authorised list of RMM and remote access tools to prevent unauthorised remote control capability | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System management
See all Guidelines for system management controls, or browse the full ASD ISM library.